GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
128 advisories
Filter by severity
The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own...
Moderate
Unreviewed
CVE-2026-72705
was published
Aug 24, 2026
The guard checker in Rocq Prover does not recheck the recursive tree representation of an...
Moderate
Unreviewed
CVE-2026-72704
was published
Aug 24, 2026
The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform...
Moderate
Unreviewed
CVE-2026-72703
was published
Aug 24, 2026
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a...
Moderate
Unreviewed
CVE-2026-19487
was published
Aug 13, 2026
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be...
Low
Unreviewed
CVE-2026-73283
was published
Aug 11, 2026
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R)...
Moderate
Unreviewed
CVE-2026-20713
was published
Aug 11, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16392
was published
Jul 21, 2026
A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto()...
Low
Unreviewed
CVE-2026-14935
was published
Jul 7, 2026
cut: -s (only-delimited) ignored when delimiter is a newline
Low
CVE-2026-35343
was published
for
uu_cut
(Rust)
Jul 6, 2026
Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist...
High
Unreviewed
CVE-2026-56328
was published
Jul 1, 2026
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special...
Critical
Unreviewed
CVE-2026-55276
was published
Jun 29, 2026
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant...
High
Unreviewed
CVE-2026-53404
was published
Jun 29, 2026
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices...
Moderate
Unreviewed
CVE-2026-56307
was published
Jun 20, 2026
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-12321
was published
Jun 16, 2026
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic...
High
Unreviewed
CVE-2026-48844
was published
May 26, 2026
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco...
Moderate
Unreviewed
CVE-2026-20171
was published
May 20, 2026
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Low
Unreviewed
CVE-2026-44928
was published
May 8, 2026
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
Low
GHSA-28xx-pppm-vqff
was published
for
github.com/ydb-platform/ydb-go-sdk/v3
(Go)
Apr 30, 2026
Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
Low
GHSA-qmq6-f8pr-cx5x
was published
for
uuid
(npm)
Apr 23, 2026
•
withdrawn
Duplicate Advisory: uutils coreutils has an Issue With its Always-Incorrect Control Flow Implementation
Low
GHSA-hj9r-8pfm-rmjj
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a...
Moderate
Unreviewed
CVE-2026-41527
was published
Apr 22, 2026
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
Moderate
CVE-2026-6608
was published
for
fschat
(pip)
Apr 20, 2026
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least...
High
Unreviewed
CVE-2026-40960
was published
Apr 16, 2026
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
Moderate
CVE-2026-40942
was published
for
dev.dsf:dsf-bpe-process-api-v2
(Maven)
Apr 15, 2026
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose...
High
Unreviewed
CVE-2026-40719
was published
Apr 15, 2026
ProTip!
Advisories are also available from the
GraphQL API